Gravityforms

Gravity Forms

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.62%
  • Veröffentlicht 15.07.2026 18:34:13
  • Zuletzt bearbeitet 15.07.2026 19:50:25

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of ...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:30
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:29
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because th...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2026 05:29:29
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fiel...

  • EPSS 0.23%
  • Veröffentlicht 02.05.2026 05:29:28
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names wh...

  • EPSS 0.24%
  • Veröffentlicht 02.05.2026 05:29:28
  • Zuletzt bearbeitet 05.05.2026 19:16:18

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by ...

  • EPSS 0.29%
  • Veröffentlicht 07.04.2026 23:25:28
  • Zuletzt bearbeitet 24.07.2026 23:10:00

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method ...

  • EPSS 0.36%
  • Veröffentlicht 07.04.2026 23:25:27
  • Zuletzt bearbeitet 24.07.2026 23:10:00

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method ...

  • EPSS 0.2%
  • Veröffentlicht 11.03.2026 09:25:43
  • Zuletzt bearbeitet 22.04.2026 21:27:27

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowin...

  • EPSS 0.67%
  • Veröffentlicht 18.11.2025 03:27:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not inclu...